Sign in

Jericho

@attrition.org
258 followers 52 following 153 posts

🐿️Vulnerability Historian / Vuln Database Guru 🐿️InfoSec recriminator 🐿️Consumer advocate / T1D 🐿️Champion of misunderstood creatures 🐿️$83,622 raised for charity.

PostsRepliesMedia
Jericho @attrition.org · 21/09/2026
Review: TajMo: Room On The Porch Tour On Thursday I was fortunate to be able to attend the Taj Mahal and Keb' Mo's Room On The Porch Tour. The two legendary Blues musicians, collectively known as TajMo, played at the Paramount Theatre in Denver. For two guys that have toured for almost 60 years…
jericho.blog
Review: TajMo: Room On The Porch Tour
On Thursday I was fortunate to be able to attend the Taj Mahal and Keb' Mo's Room On The Porch Tour. The two legendary Blues musicians, collectively known as TajMo, played at the Paramount Theatre in Denver. For two guys that have toured for almost 60 years (Taj) and the other for 50 years (Keb), they both bring serious energy and stage presence to this day.
010
Jericho @attrition.org · 02/09/2026
Lazy Movie Headlines Are Lazy At some point this year, while occasionally scrolling my Google-based news feed on my phone, I noticed that more and more articles about movies had the duration of the film in the headline. 95 minutes.. 95 minutes.. 105 minutes.. 116 minutes.. 132 minutes. Uh, why?…
jericho.blog
Lazy Movie Headlines Are Lazy
At some point this year, while occasionally scrolling my Google-based news feed on my phone, I noticed that more and more articles about movies had the duration of the film in the headline. 95 minutes.. 95 minutes.. 105 minutes.. 116 minutes.. 132 minutes. Uh, why? What normal human reads that and thinks "oh 116 minutes is perfect!" or "that's only 1.93333 hours!" This kind of lazy writing was a flashback to when I pointed out how…
000
Jericho @attrition.org · 01/09/2026
Odds Are You Are Responsible for that Traffic Slowdown I know, potentially insulting readers in the headline is not a good way to keep people interested, but it's statistically true. Until recently, when stuck in bad traffic I daydreamed about having a drone or helicopter view to see where the…
jericho.blog
Odds Are You Are Responsible for that Traffic Slowdown
I know, potentially insulting readers in the headline is not a good way to keep people interested, but it's statistically true. Until recently, when stuck in bad traffic I daydreamed about having a drone or helicopter view to see where the problem is. On occasion I am close enough to the front of the jam to see the cause; absolutely nothing.
100
Jericho @attrition.org · 31/08/2026
How Much Lipstick Can That CVE Pig Wear? Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It's a case of more and more evidence piling up and me not…
jericho.blog
How Much Lipstick Can That CVE Pig Wear?
Preface When I started writing this, I was still on the CVE editorial board, which I was removed from in 2018. That means I have been taking notes and working on this blog for over eight years. It's a case of more and more evidence piling up and me not having time to pick a time to dedicate to completing and publishing.
000
Jericho @attrition.org · 24/08/2026
Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn't hyperbole unfortunately, as the program has…
jericho.blog
Q&A: Modernizing the National Vulnerability Database in the Age of Artificial Intelligence
The last two years of the National Vulnerability Database (NVD) has been tenuous, perfidious, and an outright disaster for organizations world-wide. That isn't hyperbole unfortunately, as the program has continued to go downhill for more than two years. NVD is no longer a place to get usable vulnerability intelligence. It started back in 2024 at VulnCon, when Tanya Brewer shared an update during a talk on the state of NVD.
030
Jericho @attrition.org · 17/08/2026
Apparently Turkeys Obtained Personhood According to AI Introduction Each morning I do a quick skim of recorded events from my security system. Living in the mountains I get to enjoy clips of a wide variety of animals that visit for the last three years. That's typically bears, deer, foxes,…
jericho.blog
Apparently Turkeys Obtained Personhood According to AI
Introduction Each morning I do a quick skim of recorded events from my security system. Living in the mountains I get to enjoy clips of a wide variety of animals that visit for the last three years. That's typically bears, deer, foxes, turkeys, and a skunk. On rare occasions that includes mountain lions, coyotes, and raccoons. The security system is pretty simple with Google Nest cameras that tie into…
000
Jericho @attrition.org · 11/08/2026
Meta – The No Child Left Behind of LLMs? Intro Last month, headlines told us about a novel incident where OpenAI's agents "went rogue, escaped, and hacked" a company during testing. Some are calling it a "watershed moment" for computer security. Details quickly emerged that led some to conclude it…
jericho.blog
Meta – The No Child Left Behind of LLMs?
Intro Last month, headlines told us about a novel incident where OpenAI's agents "went rogue, escaped, and hacked" a company during testing. Some are calling it a "watershed moment" for computer security. Details quickly emerged that led some to conclude it was "remarkably easy". From there it just got more interesting, weirder, and more serious though.
000
Jericho @attrition.org · 10/08/2026
A Word on Microsoft and Vulnerability Exploitation Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or…
jericho.blog
A Word on Microsoft and Vulnerability Exploitation
Intro Microsoft Security Response Center (MSRC) is the group responsible for triage when researchers report new vulnerabilities. They handle a wide variety of other tasks, but my focus is on their analysis of vulnerabilities in one context or another. That could be the researcher's disclosure or investigating an actively exploited vulnerability in a customer environment. At some point in the past, MSRC's security advisories started adding metadata around exploitation.
000
Jericho @attrition.org · 29/07/2026
Drowning in EULA, T&S, and Privacy Policy Updates Introduction If you use a computer in almost any capacity, you have been exposed to an End-User License Agreement (EULA) before. As far as Internet lore goes they have a special place in infamy and contempt. Even before the Internet as well as the…
jericho.blog
Drowning in EULA, T&S, and Privacy Policy Updates
Introduction If you use a computer in almost any capacity, you have been exposed to an End-User License Agreement (EULA) before. As far as Internet lore goes they have a special place in infamy and contempt. Even before the Internet as well as the early days it was worse in some ways. When you went to a store and purchased software that came in a box you found yourself facing a…
021
Jericho @attrition.org · 27/07/2026
Research: Hacking-adjacent Incident from 1966 At this point I don't even remember where I obtained a really poor resolution image of a newspaper page. It's been on my computer for at least six years, likely much longer. Due to the poor resolution no matter how much you zoom and try to find a sweet…
jericho.blog
Research: Hacking-adjacent Incident from 1966
At this point I don't even remember where I obtained a really poor resolution image of a newspaper page. It's been on my computer for at least six years, likely much longer. Due to the poor resolution no matter how much you zoom and try to find a sweet spot of readability, the details were too fuzzy. Today, I decided to take another stab at it and try to search it out.
000
Jericho @attrition.org · 18/07/2026
Review: A Natural History of Empty Lots by Christopher Brown Earlier this year a good friend gave me a book, "A Natural History of Empty Lots: Field Notes from Urban Edgelands, Back Alleys, and Other Wild Places" by Christopher Brown. The book follows Brown primarily, occasionally including…
jericho.blog
Review: A Natural History of Empty Lots by Christopher Brown
Earlier this year a good friend gave me a book, "A Natural History of Empty Lots: Field Notes from Urban Edgelands, Back Alleys, and Other Wild Places" by Christopher Brown. The book follows Brown primarily, occasionally including members of family, after he moved to Austin, Texas and purchased an empty lot in an industrial section of town. From there he learns to better appreciate the nature that springs up around us.
000
Jericho @attrition.org · 09/07/2026
Random Movie/TV Thoughts and Reviews (July 2026) Spartacus: House of Ashur (2025) is a continuation of the original Spartacus series from 2010 in which Ashur is given an alternate fate than received in the original. This allows a reimagined story ending and launch into the new that finds himself…
jericho.blog
Random Movie/TV Thoughts and Reviews (July 2026)
Spartacus: House of Ashur (2025) is a continuation of the original Spartacus series from 2010 in which Ashur is given an alternate fate than received in the original. This allows a reimagined story ending and launch into the new that finds himself dominus of the very ludus that had previously owned him. Rather than just a repeat with new characters, this series stays local and branches out offering 'unseen spectacles' in the arena.
000
Jericho @attrition.org · 07/07/2026
CISA KEV’s Revolving Door Some time ago, perhaps last year or two years ago during VulnCon, I made an offhand comment about Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerability (KEV) catalog and how there were more than one vulnerability that had appeared in it…
jericho.blog
CISA KEV’s Revolving Door
Some time ago, perhaps last year or two years ago during VulnCon, I made an offhand comment about Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerability (KEV) catalog and how there were more than one vulnerability that had appeared in it and were subsequently removed. I received doubt from someone (Tod Beardsley?) that didn't think it had happened at all.
010
Jericho @attrition.org · 06/07/2026
VDBs: Pedantic Nuances on Version Tracking I am all about the pedantic nature of running a vulnerability database (VDB). It's the backbone of running one well as "simply aggregating vulnerability information" is anything but simple. I've been outspoken on the issue of perceived simplicity for at…
jericho.blog
VDBs: Pedantic Nuances on Version Tracking
I am all about the pedantic nature of running a vulnerability database (VDB). It's the backbone of running one well as "simply aggregating vulnerability information" is anything but simple. I've been outspoken on the issue of perceived simplicity for at least two decades and brought it up in various presentations and blogs. This blog is not new in that I have…
000
Jericho @attrition.org · 05/07/2026
Nature Finds a Way After moving into the mountains a few years ago I found myself being more aware of nature's diversity. I would imagine a lot of people, especially in Colorado, think they are aware and in tune with nature and I am sure many are. But going from city life to mountain life will…
jericho.blog
Nature Finds a Way
After moving into the mountains a few years ago I found myself being more aware of nature's diversity. I would imagine a lot of people, especially in Colorado, think they are aware and in tune with nature and I am sure many are. But going from city life to mountain life will open your eyes to a lot more of it.
011
Jericho @attrition.org · 04/07/2026
YouTube’s Thumbnail Generation Fraud In what I can only assume is part of the ever-growing world of AI enshitification, I began noticing an odd thing when watching videos on YouTube. When viewing content there is the primary screen with the video you are watching and on the right is a column with…
jericho.blog
YouTube’s Thumbnail Generation Fraud
In what I can only assume is part of the ever-growing world of AI enshitification, I began noticing an odd thing when watching videos on YouTube. When viewing content there is the primary screen with the video you are watching and on the right is a column with additional recommended videos as determined by their algorithm. At some point in the past year, maybe more, those thumbnails stopped being a random screen capture from the video itself.
000
Jericho @attrition.org · 03/07/2026
F5 Contributes to KEV Confusion F5 is a technology vendor that sells a variety of networking technology including security products. With a considerable security portfolio and long tenure in the industry they are well positioned to observe known exploited vulnerabilities (KEV). Their staff…
jericho.blog
F5 Contributes to KEV Confusion
F5 is a technology vendor that sells a variety of networking technology including security products. With a considerable security portfolio and long tenure in the industry they are well positioned to observe known exploited vulnerabilities (KEV). Their staff frequently write blogs about threat actor activity, exploit campaigns, and associated topics. Unfortunately, while they have great insight into this activity, their ability to convey that information in a clear manner is seriously lacking.
100
Jericho @attrition.org · 02/07/2026
We’re Losing the “Cyber” War to Ourselves It's hard to pinpoint where the concept of cyberwar originated. In roundabout ways it likely goes back many decades in fiction. As far as citations go, some believe a seminal work is titled Unrestricted Warfare by Qiao Liang and Wang Xiangsui, two colonels…
jericho.blog
We’re Losing the “Cyber” War to Ourselves
It's hard to pinpoint where the concept of cyberwar originated. In roundabout ways it likely goes back many decades in fiction. As far as citations go, some believe a seminal work is titled Unrestricted Warfare by Qiao Liang and Wang Xiangsui, two colonels in the People's Liberation Army (PLA). Regardless of when the premise started, the computer-based cold war has been going full steam for two decades or more.
010
Jericho @attrition.org · 01/07/2026
And AI Tech Bros Still Want to Gamble… If you follow even the headlines for so-called "AI" developments, you may have caught a few that talked about how some AI insiders say there is a chance that the technology they are developing will "destroy humanity". Of course, that term is subjective and…
jericho.blog
And AI Tech Bros Still Want to Gamble…
If you follow even the headlines for so-called "AI" developments, you may have caught a few that talked about how some AI insiders say there is a chance that the technology they are developing will "destroy humanity". Of course, that term is subjective and could vary considerably from person to person. Does it mean it will destroy what makes us human, the creativity and drive?
000
Jericho @attrition.org · 30/06/2026
Save the Earth One Napkin at a Time Over the years I have certainly thought about the concept "healing by a thousand bandaids", as a counter idiom to "death by a thousand cuts", while not writing as much about it. I have blog notes for various things in the spirit of this and have used it…
jericho.blog
Save the Earth One Napkin at a Time
Over the years I have certainly thought about the concept "healing by a thousand bandaids", as a counter idiom to "death by a thousand cuts", while not writing as much about it. I have blog notes for various things in the spirit of this and have used it consistently at work to describe the idea of using small bits of automation for a greater impact.
000
Jericho @attrition.org · 29/06/2026
The Loquacious Introvert This is my 1,000th post on this blog! Not counting this post, that is 893,353 words written here over 38 years. Of course, this blog hasn't been around that long but I made an effort the last few years to consolidate all of my writing in one place and date it accordingly.…
jericho.blog
The Loquacious Introvert
This is my 1,000th post on this blog! Not counting this post, that is 893,353 words written here over 38 years. Of course, this blog hasn't been around that long but I made an effort the last few years to consolidate all of my writing in one place and date it accordingly. That means the first "post" of this blog is…
140
Jericho @attrition.org · 28/06/2026
2026 East Coast Drive (Part 8: Random Notes) The final post in my series on the recent East coast drive through five states has broader observations and thoughts. With over two thousand miles of driving it gives you plenty of time to think and observe. In no particular order… Professional Driver…
jericho.blog
2026 East Coast Drive (Part 8: Random Notes)
The final post in my series on the recent East coast drive through five states has broader observations and thoughts. With over two thousand miles of driving it gives you plenty of time to think and observe. In no particular order… Professional Driver Responsibility I think that all 18-wheel trucks should be required by federal law to have a phone number you can call to report dangerous driving or other issues.
000
Jericho @attrition.org · 26/06/2026
Captain Obvious Audits the NVD During my recent trip to the East Coast several people linked an article from Recorded Future to me since it was on a topic I have written extensively about. The article covered a May 26 report from the Office of the Inspector General (OIG) at the Department of…
jericho.blog
Captain Obvious Audits the NVD
During my recent trip to the East Coast several people linked an article from Recorded Future to me since it was on a topic I have written extensively about. The article covered a May 26 report from the Office of the Inspector General (OIG) at the Department of Commerce that was summarized as "mistakes have been made" in the operation of National Vulnerability Database (NVD).
000
Jericho @attrition.org · 22/06/2026
2026 East Coast Drive (Part 3: VA / DC) June 5 (Friday) From Richland, Virginia it was time to head North toward Washington D.C. The day was primarily stopping at a few towns to check out stores and drive through the areas to get a feel for them. I had driven through this area in 2022 as part of…
jericho.blog
2026 East Coast Drive (Part 3: VA / DC)
June 5 (Friday) From Richland, Virginia it was time to head North toward Washington D.C. The day was primarily stopping at a few towns to check out stores and drive through the areas to get a feel for them. I had driven through this area in 2022 as part of another cross country trip but this time headed in a different direction with time to check out more of the area.
000
Jericho @attrition.org · 21/06/2026
2026 East Coast Drive (Part 2: North Carolina / Virginia) June 3 (Wednesday) After the convention I drove back to Wilmington, North Carolina to check out a few shops and grab lunch along the river. The old downtown area is nice to walk and has a lot to see including art and a battleship. Being…
jericho.blog
2026 East Coast Drive (Part 2: North Carolina / Virginia)
June 3 (Wednesday) After the convention I drove back to Wilmington, North Carolina to check out a few shops and grab lunch along the river. The old downtown area is nice to walk and has a lot to see including art and a battleship. Being back in the South also gave a bit of nostalgia seeing Waffle House again, especially with all the…
000
Jericho @attrition.org · 20/06/2026
2026 East Coast Drive (Part 1: NaClCON) Pre-game For the first half of June I attended NaClCON and then drove through five states and the District of Columbia. The trip began with a rare flight that required a layover as Wilmington, North Carolina is a small regional airport. That put me through…
jericho.blog
2026 East Coast Drive (Part 1: NaClCON)
Pre-game For the first half of June I attended NaClCON and then drove through five states and the District of Columbia. The trip began with a rare flight that required a layover as Wilmington, North Carolina is a small regional airport. That put me through O'Hare which I despise due to past trips that left me stranded there overnight. Fortunately the flight was uneventful other than having to wake up at 4:30am to catch an early flight.
000
Jericho @attrition.org · 19/06/2026
My Quest for the White Squirrel! I recently attended NaClCON in Carolina Beach, North Carolina. After the con concluded I took a drive through North Carolina, Virginia, Washington D.C., West Virginia, Kentucky, Tennessee, and back through North Carolina to fly out. Between June 3rd and June 12th I…
jericho.blog
My Quest for the White Squirrel!
I recently attended NaClCON in Carolina Beach, North Carolina. After the con concluded I took a drive through North Carolina, Virginia, Washington D.C., West Virginia, Kentucky, Tennessee, and back through North Carolina to fly out. Between June 3rd and June 12th I drove around two thousand miles to see a couple states I had never been to as well as areas of other states I had not.
000
Jericho @attrition.org · 18/06/2026
Colorado Voting System Irregularities & Continued Rigging Earlier this year I wrote about how the Colorado voting system is effectively "rigged" to enforce a two-party system. In that I said "In Colorado, if you are not registered with political affiliation, you are given two ballots; one Democrat…
jericho.blog
Colorado Voting System Irregularities & Continued Rigging
Earlier this year I wrote about how the Colorado voting system is effectively "rigged" to enforce a two-party system. In that I said "In Colorado, if you are not registered with political affiliation, you are given two ballots; one Democrat and one Republican. This forces you to vote along party lines even if you do not fully support either party.
000
Reposted by Jericho
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 15/06/2026
I just realized that I'm personally "credited" in April's Microsoft Patch Tuesday with a CVE-less "Defense-in-depth" update. The vulnerability? CAB files downloaded from the internet do not write the MotW for files extracted from them. I reported this to […] [Original post on infosec.exchange]
122
Jericho @attrition.org · 16/06/2026
@f5labs.bsky.social re: www.f5.com/labs/article... Are you using "AI" to do these? e.g. "Threat Details and IOCs" and "CVE-2026-35273, CVE-2026-46695, CVE-2026-46703, CVE-2026-48558, CVE-2026-50545" has nothing to do with the section above, and those CVEs are largely not for the software listed.
f5.com
Weekly Threat Bulletin – June 17th, 2026
These are the top threats you should know about this week.
011
Jericho @attrition.org · 31/05/2026
MSRC; Tell The Whole Story Please Every so often, it seems that Microsoft Security Response Center (MSRC) likes to stick their proverbial foot in their mouth on the topic of vulnerability disclosure. The root issue is that collectively, MSRC does not seem to appreciate either their own history or…
jericho.blog
MSRC; Tell The Whole Story Please
Every so often, it seems that Microsoft Security Response Center (MSRC) likes to stick their proverbial foot in their mouth on the topic of vulnerability disclosure. The root issue is that collectively, MSRC does not seem to appreciate either their own history or the bigger picture. As such they have a myopic view on the topic. The latest comes in the…
041
Jericho @attrition.org · 26/05/2026
Mythos Needs to Shift Left Over the years I have been part of many discussions around a classic debate around red team versus blue team, the value of penetration testing, and the value they each bring. I started my InfoSec career in 1996 doing pentesting (aka red teaming) a couple years before it…
jericho.blog
Mythos Needs to Shift Left
Over the years I have been part of many discussions around a classic debate around red team versus blue team, the value of penetration testing, and the value they each bring. I started my InfoSec career in 1996 doing pentesting (aka red teaming) a couple years before it really exploded. For nine years that was my life and it often meant working crazy hours.
011
Jericho @attrition.org · 25/05/2026
Vulnerability Embargos Are Dead Introduction When a researcher finds a security vulnerability that impacts more than one vendor, and they wish to coordinate disclosure with both, it creates a situation where an embargo must be put in place. In this context that simply means that all three parties…
jericho.blog
Vulnerability Embargos Are Dead
Introduction When a researcher finds a security vulnerability that impacts more than one vendor, and they wish to coordinate disclosure with both, it creates a situation where an embargo must be put in place. In this context that simply means that all three parties agree not to make the information public until a given date. This is done to allow both vendors to have a fix ready before publication.
000
Jericho @attrition.org · 20/05/2026
Calif’s Bold Claims; Missing Receipts Here we go again, more Mythos rumors and claims to unpack. I wrote a lengthy blog on Anthropic, Glasswing, and Mythos just over a month ago but this is about a very specific event and set of claims. A significant reason I am writing this is due to what I…
jericho.blog
Calif’s Bold Claims; Missing Receipts
Here we go again, more Mythos rumors and claims to unpack. I wrote a lengthy blog on Anthropic, Glasswing, and Mythos just over a month ago but this is about a very specific event and set of claims. A significant reason I am writing this is due to what I believe are poorly written headlines that are based in misunderstanding and/or attempting to sound more dramatic than warranted.
000
Jericho @attrition.org · 20/05/2026
Noise2Signal Podcast: Which Does the Squirrel Bring? For those not familiar, Mehul Revankar recently started a podcast named Noise2Signal. While there are a lot of podcasts out there and it is easy to lose track, this one stands out as Mehul has connections with a lot of folks that are significant…
jericho.blog
Noise2Signal Podcast: Which Does the Squirrel Bring?
For those not familiar, Mehul Revankar recently started a podcast named Noise2Signal. While there are a lot of podcasts out there and it is easy to lose track, this one stands out as Mehul has connections with a lot of folks that are significant in the history of information security. In fact, he interviewed Renaud Deraison who created Nessus and was one of the founders of Tenable.
000
Jericho @attrition.org · 14/05/2026
Amazon Auto-buy: A Slick New Feature For half a year now, I have been using a third-party site (Keepa) to track movie prices on Amazon (and a few other sites), waiting for them to drop to the price I will pay. New movies are often released on physical media at fairly absurd rates. Almost fifty…
jericho.blog
Amazon Auto-buy: A Slick New Feature
For half a year now, I have been using a third-party site (Keepa) to track movie prices on Amazon (and a few other sites), waiting for them to drop to the price I will pay. New movies are often released on physical media at fairly absurd rates. Almost fifty dollars for a new release when it was $17 in the theatre?
011
Jericho @attrition.org · 08/05/2026
Security vs Security Theatre; A Lesson for Abbott Security theater, as defined by Wikipedia, "is the practice of implementing security measures that are considered to provide the feeling of improved security while doing little or nothing to achieve it." This is a common term used by information…
jericho.blog
Security vs Security Theatre; A Lesson for Abbott
Security theater, as defined by Wikipedia, "is the practice of implementing security measures that are considered to provide the feeling of improved security while doing little or nothing to achieve it." This is a common term used by information security professionals and has been a concept for a long, long time. I recently pointed it out in my interaction with CenturyLink when canceling service.
110
Jericho @attrition.org · 07/05/2026
The NVD Shell Game & Schrödinger’s Enriched Vulnerability I know, yet another blog about the National Vulnerability Database's (NVD) ever-changing numbers?! That's right, and I am not talking about the changes between April 14 and 15th. The numbers changed significantly because of the way NVD…
jericho.blog
The NVD Shell Game & Schrödinger’s Enriched Vulnerability
I know, yet another blog about the National Vulnerability Database's (NVD) ever-changing numbers?! That's right, and I am not talking about the changes between April 14 and 15th. The numbers changed significantly because of the way NVD displayed statistics on their dashboard before a dramatic change in their enrichment policy. At VulnCon 2026, Harold Booth updated attendees about NVD's enrichment efforts after two years of a steadily growing backlog of vulnerabilities that had not received any enrichment. 
000
Jericho @attrition.org · 03/05/2026
The Night I Almost Died I write a lot. Most recently it has been about information security, movie reviews, so-called AI, and a few other topics. It's been four years since I blogged about my poor experience with Abbott's Libre2 glucose sensor technology and all the shortcomings. Since then I have…
jericho.blog
The Night I Almost Died
I write a lot. Most recently it has been about information security, movie reviews, so-called AI, and a few other topics. It's been four years since I blogged about my poor experience with Abbott's Libre2 glucose sensor technology and all the shortcomings. Since then I have tweeted to them a considerable amount when my continuous glucose monitor (CGM) dies, which is an increasing occurrence.
010
Jericho @attrition.org · 02/05/2026
Starfleet Academy; The Review Starfleet Academy (SA), the latest TV show in the Star Trek line, debuted this year with a lot of fanfare and a fair share of drama. The show almost immediately hit the news with cries of it being "too woke". The Washington Times headline called it a "woke culture war…
jericho.blog
Starfleet Academy; The Review
Starfleet Academy (SA), the latest TV show in the Star Trek line, debuted this year with a lot of fanfare and a fair share of drama. The show almost immediately hit the news with cries of it being "too woke". The Washington Times headline called it a "woke culture war casualty" and Outkick said the show hit "
120
Jericho @attrition.org · 01/05/2026
Why Data From So Many Breaches Never Sees the Light of Day Months ago I was chatting with a colleague about a recent data leak (a.k.a. Data breach), as we tend to do in this industry. Those terms are defined by Microsoft as "an unauthorized disclosure of sensitive, confidential, or personal…
jericho.blog
Why Data From So Many Breaches Never Sees the Light of Day
Months ago I was chatting with a colleague about a recent data leak (a.k.a. Data breach), as we tend to do in this industry. Those terms are defined by Microsoft as "an unauthorized disclosure of sensitive, confidential, or personal information from an organization’s systems or networks to an external party". Any time I see an article about data breaches I have flashbacks, and fortunately not too much PTSD, as seen via the next few paragraphs. 
000
Jericho @attrition.org · 30/04/2026
InfoSec News (ISN) Mail List History As early as 1996, I created a mail list called InfoSec News (ISN) which initially was to share news about the industry. At the time, there were no online news sites covering the topic with any regularity and most were hobbies at best. So the original list had…
jericho.blog
InfoSec News (ISN) Mail List History
As early as 1996, I created a mail list called InfoSec News (ISN) which initially was to share news about the industry. At the time, there were no online news sites covering the topic with any regularity and most were hobbies at best. So the original list had many articles that I had typed in by hand from print InfoSec magazines.
021
Jericho @attrition.org · 29/04/2026
An AI agent destroyed … hey wait a minute! Yesterday many people ran across a headline that was shocking, and repetitive. This time it read "‘Gone in 9 seconds’: Claude-powered AI agent deletes startup’s entire database". For myself, the first thing I had to do was check the date of the article…
jericho.blog
An AI agent destroyed … hey wait a minute!
Yesterday many people ran across a headline that was shocking, and repetitive. This time it read "‘Gone in 9 seconds’: Claude-powered AI agent deletes startup’s entire database". For myself, the first thing I had to do was check the date of the article because I swore I had just read about this recently. Yep, April 28 so it's a new one!
100
Jericho @attrition.org · 28/04/2026
Don’t Call Me Boss I don't remember when it started but it was easily five to ten years ago. I'd be in a restaurant typically and a server or cashier would call me 'boss'. It bothered me from day one because it usually came from a younger kid who presumably didn't understand all of the…
jericho.blog
Don’t Call Me Boss
I don't remember when it started but it was easily five to ten years ago. I'd be in a restaurant typically and a server or cashier would call me 'boss'. It bothered me from day one because it usually came from a younger kid who presumably didn't understand all of the connotations behind the word in that context. I certainly felt it was inappropriate but only said something a few times when I felt the person might be receptive, listen to my explanation, and hopefully change.
010
Jericho @attrition.org · 27/04/2026
Security Software: Holding the Vault Door Open for Criminals I have been consistently tracking a fun metric around vulnerabilities since March 19, 2024. Before that I would occasionally mention it during talks or chat, but I don't think I formally blogged about it before this and didn't track the…
jericho.blog
Security Software: Holding the Vault Door Open for Criminals
I have been consistently tracking a fun metric around vulnerabilities since March 19, 2024. Before that I would occasionally mention it during talks or chat, but I don't think I formally blogged about it before this and didn't track the exact number. So here we are to discuss the prevalence of vulnerabilities in security software, the very thing designed to protect us.
041
Jericho @attrition.org · 22/04/2026
Another Wave of Random Thoughts ATM ATMs have way too many options for many users, and definitely for most uses of the machines by volume. Sometimes, when I put my card in, why are you asking what language I want to use? The same one as last time maybe? And for someone who has the same exact…
jericho.blog
Another Wave of Random Thoughts
ATM ATMs have way too many options for many users, and definitely for most uses of the machines by volume. Sometimes, when I put my card in, why are you asking what language I want to use? The same one as last time maybe? And for someone who has the same exact transaction 95% of the time, give me a single button that just says "repeat last transaction" and display what it is.
010
Jericho @attrition.org · 17/04/2026
Attending NaClCON (naclcon.com) in May/June? Even if not attending... do you have any -old- neat hacker/phreaker swag you can donate? During the closing ceremony, I am looking to do quick live-auction bidding for charity for them! This is my donation to the cause!
194
Jericho @attrition.org · 17/04/2026
NVD Gives Up Since 2024, representatives from NIST's National Vulnerability Database (NVD) have given a presentation at VulnCon with updates to the program. This has been where news broke about significant changes, admissions, and omissions. The talks, typically 30 minutes, are certainly not…
jericho.blog
NVD Gives Up
Since 2024, representatives from NIST's National Vulnerability Database (NVD) have given a presentation at VulnCon with updates to the program. This has been where news broke about significant changes, admissions, and omissions. The talks, typically 30 minutes, are certainly not enough time to tell us what the industry needs to know and leaves no time for Q&A despite there being a considerable amount.
155
Reposted by Jericho
Steve Christey Coley @realsushidude.bsky.social · 14/04/2026
WHO DID THIS!?!? 🤪😅🤣 #VulnCon2026 #VulnCon26
a sticker of a cartoon squirrel in a robe like a Star Wars character. The squirrel's eyes are bright red. Sticker says "He who must not be named"
2101
Jericho @attrition.org · 15/04/2026
Anthropic, Mythos, and the Dark Reality No One Is Talking About If I had a nickel for every time Anthropic's new Project Glasswing / Mythos initiative came up in conversation or I was asked directly about it in the last few days, I would have a shit ton of nickels! Let's dive into it… first with…
jericho.blog
Anthropic, Mythos, and the Dark Reality No One Is Talking About
If I had a nickel for every time Anthropic's new Project Glasswing / Mythos initiative came up in conversation or I was asked directly about it in the last few days, I would have a shit ton of nickels! Let's dive into it… first with brief observations about the announcements and available information, other's opinions, then a broader opinion of my own on where this is all going.
141